Child Centred Business, GDPR, Social Media

Taking Photos of Children: Are Your Permissions Up to Date?

Annabel Kaye
Children taking part in a music activity with their faces turned away from the camera

Taking photos of children can be a great way to market your activities. Photographs and videos are powerful ways to show parents what happens at your children’s activities. They can capture the fun, confidence and sense of belonging far better than a paragraph of marketing copy.

But publishing an identifiable image of a child is not a risk-free activity—particularly when it is placed on a public website or social-media platform.

A photograph that seemed harmless when your permissions were written may now be copied, downloaded, altered or used by AI tools in ways neither you nor the child’s parents expected.

That makes this a good time to check whether your paperwork and everyday practices still match what actually happens to the images you collect.

Permission is not just a tick box

Asking a parent whether you may take or use photographs is only part of the job.

People need sufficiently clear information to understand what they are agreeing to. “Marketing purposes” may not adequately explain that an image could appear on a public website, Facebook, Instagram, printed leaflets or advertising materials.

Your wording should reflect what you genuinely do—not what an old form copied from somewhere else happens to say.

You should also distinguish between taking photographs for operational reasons and publishing them for promotional purposes. Different uses can create different risks and may need to be handled differently.

Consent will not necessarily be the correct data-protection lawful basis for every image or every use. However, if you ask for consent or permission, you must manage it properly and avoid making promises that cannot be kept.

What happens when permission changes?

A parent may withdraw permission because family circumstances have changed, the child is at risk, or they simply no longer want the image used.

You should be able to find the relevant photographs and remove them from places you control.

But complete erasure may be impossible once an image has been published. Other people may have:

  • downloaded it;
  • taken a screenshot;
  • shared or reposted it;
  • printed it; or
  • stored it in a cache or archive.

Your privacy information and permission wording should explain those practical limits honestly. Promising that an image can always be removed from the internet is a promise no sensible business should make.

We discuss this in more detail in our article for the Institute of Children’s Activity Providers.

Check what your platforms can do

Do not assume that retaining copyright means a platform has no rights over an image.

Website services, design tools, cloud-storage providers and social-media platforms may require a licence to host, reproduce, adapt or distribute uploaded material. Their terms may also change as they introduce new AI features.

You should monitor whether the platforms you use claim rights to process images for AI editing, model development or other purposes, and change your approach where those terms create an unacceptable risk.

That might mean limiting what you upload, changing a setting, using a different provider or deciding that some children’s images should not be placed on that platform at all. Our article on Instagram AI and children’s photos shows how these risks can arise in practice.

Can the child still be identified?

Removing a child’s name does not necessarily make a photograph anonymous.

A child might still be identified from:

  • a school or activity uniform;
  • the venue;
  • a distinctive event;
  • location information;
  • other people in the image; or
  • the text published beside it.

Photographs taken from behind, group photographs and blurred faces can sometimes reduce risk, but they are not automatically anonymous or safe. Look at the complete context rather than relying on one visual trick.

Your practices need to keep changing

Technology and legal guidance are developing rapidly, and substantial changes are expected over the next 18 months.

This is not something to review once and then forget. Revisit your permissions, privacy information, platform settings and working practices regularly—particularly when you begin using a new marketing channel or AI feature.

The question is no longer simply, “Did a parent tick the box?” It is:

Do we understand where this image may go, what may happen to it and whether using it is still appropriate? Have we explained that clearly to the parent giving permission?

Download the free check-up

Our Children’s Images and Marketing Check-up helps you review:

  • what your permission wording actually covers;
  • where photographs and videos may be published;
  • whether children can be identified through names, uniforms, locations or accompanying text;
  • what happens when permission is withdrawn;
  • how staff, freelancers and photographers handle images;
  • whether old images are still being used;
  • what the terms of your chosen platforms allow; and
  • the growing risks created by AI editing, manipulation and deepfakes.

Download the Children’s Images and Marketing Check-up

If the check-up identifies gaps in your policies, permissions or working practices, explore KoffeeKlatch’s GDPR support for children’s activity providers.

For occasional updates about children’s data privacy, use the mailing-list sign-up form on this page.

We won’t add your details to any other list or share them. You can unsubscribe at any time. For more information see our Data Privacy Policy